Announcing C1 Transform 2026
Agent Runtime Governance

Govern what agents actually do

Intent-based access control. Each agent scoped to its task, every call judged, every action owned.

Govern what agents actually do
Every action an agent takes looks the same, whether it's routine work or an attack.

C1 governs the call itself, enforcing guardrails on every agent action: control at the point where AI acts.

Runtime control for every agent

Full coverage without touching agent code

Secure every agent without modifying a single line of code. Register MCP servers and internal tools automatically, then enforce policy on every request through one control point.

Explore AI Access Gateway

Easily manage every tool call

Give every agent only the tools it needs. Assign governed toolsets, review permissions like any other access, and eliminate guesswork with intent-based authorization.

Catch dangerous calls before they run

Stop dangerous commands before they execute by detecting private data access, prompt injection, and exfiltration attempts before damage occurs.

Turn on enforcement with confidence

Roll out AI guardrails without disrupting the business. Test policies in observe mode first, then block, redact, or require approval with confidence.

Audit-ready, down to every agent action

Prove every AI action was governed. Every decision records the agent, tool, policy, owner, and outcome—giving security teams an audit trail they can trust.

95%

of enterprises now run AI agents autonomously

19%

of enterprises adjust access continuously based on policy and context; the rest let it drift until an incident surfaces it

Companies like Instacart, Ramp, Zscaler, and Brex scale AI agents with C1.

C1's 2026 Future of Identity Report

How C1 governs agents at runtime

Route the traffic

Point agent tool traffic at the identity-aware gateway. No agent rewrites, no SDK inside your agents.

Scope the access

Each tool is classified on a scale from read-only to dangerous, with your review and override, and each agent gets only what its job needs. Auto-approve the reads, gate what changes or exposes.

Judge every call

Guardrails score each call and enforce your posture: block, hold for approval, or redact. A check that can't run holds the call.

Prove what happened

Every action lands as one audit event naming the agent, the tool, the policy that decided, and the outcome.

FAQs

Latest on the platform

C1 for Agent Runtime Governance

Brief

C1 for Agent Runtime Governance

Each agent scoped to its task. Every call checked. Every action owned.

Introducing agentic security and intelligence: close identity risk with C1

Blog

Introducing agentic security and intelligence: close identity risk with C1

C1's agentic security and intelligence detects identity risk across people, service accounts, workloads, and AI agents, then routes every finding through governed remediation or the tools your team already uses.

AI Agent Runtime Security: Governing What Agents Do

Guide

AI Agent Runtime Security: Governing What Agents Do

AI agent runtime security governs what an agent does while it runs. Learn tool call authorization, risk scoring, approval holds, and how to revoke access.

Govern every action. Trust every outcome.